First published: Fri Apr 13 2018(Updated: )
A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ikiwiki | 3.20190228-1 3.20200202.3-1 | |
Ikiwiki Ikiwiki | <3.20170111 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.